Legal Register
Visual Infographic
I-06 Consent & Purpose ๐Ÿ‘ค Product Managers, UX Designers & Legal Counsel

Two Doors, No Third (Legal Processing Grounds)

Consent under Section 6 vs Section 7 Closed-List Legitimate Uses

India's DPDP Act recognizes only TWO legal doors for processing digital personal data: Door 1 (Valid Consent under Section 6) and Door 2 (The Closed List of Certain Legitimate Uses under Section 7). Crucially, there is NO Door 3: DPDP deliberately omits GDPR's open-ended 'Legitimate Interest' balancing test or 'Contractual Necessity' ground. Any processing that cannot fit within Section 7's 9 statutory clauses MUST obtain granular, affirmative consent under Section 6.

Statutory Source: Ch. 3 ยง6, Ch. 8
Archetype: state machine
I-06 DiagramArchetype: STATE MACHINE

Two Doors, No Third (Legal Processing Grounds)

DOOR 1Primary Baseline

Door 1: Valid Consent (s.6)

  • โœ“Free, Specific, Informed, Unconditional, Unambiguous
  • โœ“Affirmative Action (no pre-ticked boxes)
  • โœ“Accompanied or preceded by Section 5 Notice in 22 languages
  • โœ“Withdrawable at any time via s.6(4)
DOOR 2Closed List

Door 2: Section 7 Closed List (Certain Legitimate Uses)

s.7(a) Specified Purpose with Voluntary Provision
s.7(b) State Subsidies, Benefits & Services
s.7(c) State Functions & Sovereign Security
s.7(d) Compliance with Indian Legal Orders
s.7(e) Judgments & Decrees of Indian Courts
s.7(f) Medical Emergencies involving Threat to Life
s.7(g) Epidemic, Disease & Public Health Disasters
s.7(h) Disaster Relief & Public Safety
s.7(i) Employment & Corporate Asset Protection
DOOR 3DOES NOT EXIST

Door 3: Non-Existent Door

NO Legitimate Interests, NO Performance of Contract basis, NO Commercial Necessity ground.

โš ๏ธ Attempting to process data under generic "legitimate interest" is an immediate statutory breach under DPDP.

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ Never cite 'Legitimate Interest' in Indian privacy notices; it is legally void under DPDP.
โœฆ Contractual terms cannot bypass the requirement for itemized consent under Section 6.
โœฆ Employment data processing is strictly limited to employment purposes and safeguarding employers.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 4(1)Section 6Section 7(a)Section 7(b)Section 7(c)Section 7(d)Section 7(e)Section 7(f)Section 7(g)Section 7(h)Section 7(i)

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Audit all enterprise data processing activities and map them to either s.6 or s.7.
  2. Migrate any GDPR 'Legitimate Interest' processes to explicit, granular consent flows.
  3. Segment HR data pipelines under s.7(i) separately from customer consent ledgers.

Enterprise Traps & Failure Modes

  • โš ๏ธ Using pre-ticked consent checkboxes or bundled contractual acceptance.
  • โš ๏ธ Relying on s.7(a) voluntary provision for downstream analytics or advertising.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ Purpose & Legal Basis Ledger (purpose-decisions.json)
๐Ÿ“„ Consent Architecture Specification